Authorization bypass through user-controlled key in Kibana - CVE-2026-72666

 

Authorization bypass through user-controlled key in Kibana - CVE-2026-72666

Published: August 13, 2026


Vulnerability identifier: #VU142333
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72666
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and execute unauthorized queries on managed hosts.

The vulnerability exists due to authorization bypass through user-controlled key in Kibana Osquery live query functionality when handling requests to run live queries across Kibana spaces. A remote user can send a crafted request to execute queries against Elastic Agents assigned to a space the user cannot access to disclose sensitive information and execute unauthorized queries on managed hosts.

Exploitation requires the ability to run Osquery live queries in at least one Kibana space.


Affected software

Kibana

How to mitigate CVE-2026-72666

Install security update from vendor's website.

Kibana - update to 9.4.5

External References

Related Security Bulletins